SANU P.L

31 exploits Active since Jan 2022
CVE-2021-46070 NOMISEC MEDIUM WORKING POC
Vehicle Service Management System 1.0 - XSS
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service Requests Section in login panel.
CVSS 4.8
CVE-2021-46075 NOMISEC HIGH WRITEUP
Sourcecodester Vehicle Service Mgmt 1.0 - Privilege Escalation
A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access the admin resources and perform CRUD Operations.
CVSS 7.2
CVE-2021-46071 NOMISEC MEDIUM WORKING POC
Vehicle Service Management System 1.0 - XSS
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Category List Section in login panel.
CVSS 4.8
CVE-2021-46079 NOMISEC HIGH WRITEUP
Sourcecodester Vehicle Service Mgmt 1.0 - File Upload
An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload malicious files leading to Html Injection.
CVSS 7.2
CVE-2021-46076 NOMISEC HIGH WORKING POC
Sourcecodester Vehicle Service Management System 1.0 - Code Injection
Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in multiple endpoints it leading to Code Execution.
CVSS 8.8
CVE-2021-45744 NOMISEC MEDIUM WRITEUP
Bludit < 3.13.1 - Stored Cross-Site Scripting via Tags Field
A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.
CVSS 5.4